Description
Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block. An unauthenticated visitor could recover configuration values emitted by a restricted sub-block's asset registration — such as a site's configured Google Maps API key — from any public page embedding an affected Stack, Container, or layout area, despite the block-level permission restriction. Any sub-block type whose asset or header hooks output configuration values is affected.  The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.
Published: 2026-09-08
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure due to Missing Authorization
Action: Apply Patch
AI Analysis

Impact

Concrete CMS versions earlier than 9.5.3 register view assets for every sub‑block within a Stack, Container, or layout area without verifying that the requesting user has permission to view that sub‑block. The process emits configuration values, such as a site’s Google Maps API key, which can then be retrieved by any visitor of a public page that contains an affected Stack, Container, or layout area. The vulnerability is a direct result of missing authorization checks and allows an attacker to read sensitive configuration data that should be protected at the block level. This leads to the disclosure of potentially critical information, which can be used to facilitate further attacks, such as API abuse or privilege escalation. The weakness is classified under CWE-862, Missing Authorization.

Affected Systems

Concrete CMS installations running a version earlier than 9.5.3 are affected. The vulnerability applies to any sub‑block type whose asset or header hooks output configuration values. Public pages that embed an affected Stack, Container, or layout area provide a path to exploitation.

Risk and Exploitability

The CVSS v4.0 score is 6.3, indicating a medium severity. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. Attackers do not need authentication or special privileges; any unauthenticated visitor to a public page containing an affected block can trigger the vulnerability and retrieve restricted configuration data. The risk is therefore moderate, with potential for significant impact if sensitive values are exposed.

Generated by OpenCVE AI on September 9, 2026 at 09:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later, which implements proper authorization checks for sub‑block asset registration.
  • Immediately scan public pages for exposed configuration values and clear or rotate any sensitive API keys that may have been leaked.
  • As a temporary measure, remove or disable the asset/header hooks of blocks that emit sensitive configuration data until an upgrade can be performed.

Generated by OpenCVE AI on September 9, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Stack/Container Sub-Block Asset Registration Concrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Container Sub-Block Asset Registration

Tue, 08 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block. An unauthenticated visitor could recover configuration values emitted by a restricted sub-block's asset registration — such as a site's configured Google Maps API key — from any public page embedding an affected Stack, Container, or layout area, despite the block-level permission restriction. Any sub-block type whose asset or header hooks output configuration values is affected.  The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.
Title Missing Authorization in Stack/Container Sub-Block Asset Registration
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-10T14:45:53.105Z

Reserved: 2026-08-27T18:21:25.200Z

Link: CVE-2026-81904

cve-icon Vulnrichment

Updated: 2026-09-10T14:45:40.316Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T22:19:16.107

Modified: 2026-09-10T15:17:47.090

Link: CVE-2026-81904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T02:15:10Z

Weaknesses